CVEs from 2018

3,853 normalized CVEs published or assigned in this year.

Total
3,853
critical
critical 224
high
high 267
medium
medium 224
low
low 32
% Critical
5.8%
% with KEV
2.3%
% with exploit
2.3%

Top products

  • erpnext 4
  • terminal_services_manager 1
  • ultraiso 1
  • dolibarr_erp\/crm 1
  • gitbucket 1
  • pdfunite 1
  • qemu 1
  • virtualization_manager 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2018-9055 low 2.5 denial of service in jasper archsuse
CVE-2018-20225 low 2.5 arbitrary code execution in python-pip archsuse
CVE-2018-10932 low 2.5 lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the … suserockylinuxdebian
CVE-2018-7174 low 2.5 An issue was discovered in xpdf 4.00. An infinite loop in XRef::Xref allows an attacker to cause denial of service because loop detection exists only for tables, not streams. archsusedebian
CVE-2018-7453 low 2.5 Infinite recursion in AcroForm::scanField in AcroForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file due to lack of loop checking, as demonstrated by pdftohtml. archsusedebian
CVE-2018-1071 low 2.5 zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service. archsusedebian
CVE-2018-7452 low 2.5 A NULL pointer dereference in JPXStream::fillReadBuf in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. archsusedebian
CVE-2018-0734 low 2.5 The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in Ope… archsusedebian
CVE-2018-7454 low 2.5 A NULL pointer dereference in XFAForm::scanFields in XFAForm.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. archsusedebian
CVE-2018-12558 low 2.5 The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that c… archdebian
CVE-2018-18445 low 2.5 In the Linux kernel 4.14.x, 4.15.x, 4.16.x, 4.17.x, and 4.18.x before 4.18.13, faulty computation of numeric bounds in the BPF verifier permits out-of-bounds memory accesses because adjust_scalar_min… archsusedebian
CVE-2018-7455 low 2.5 An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. archdebian
CVE-2018-7173 low 2.5 A large loop in JBIG2Stream::readSymbolDictSeg in xpdf 4.00 allows an attacker to cause denial of service via a specific file due to inappropriate decoding. archsusedebian
CVE-2018-7175 low 2.5 An issue was discovered in xpdf 4.00. A NULL pointer dereference in readCodestream allows an attacker to cause denial of service via a JPX image with zero components. archsusedebian
CVE-2018-8956 low 2.5 ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packet… archsusedebian
CVE-2018-0502 low 2.5 An issue was discovered in zsh before 5.6. The beginning of a #! script file was mishandled, potentially leading to an execve call to a program named on the second line. archsusedebian
CVE-2018-13259 low 2.5 An issue was discovered in zsh before 5.6. Shebang lines exceeding 64 characters were truncated, potentially leading to an execve call to a program name that is a substring of the intended one. archsusedebian
CVE-2018-0732 low 2.5 During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long pe… archsusedebian
CVE-2018-0737 low 2.5 The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key gen… archsusedebian
CVE-2018-20482 low 2.5 GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c)… archsusedebian
CVE-2018-5388 low 2.5 In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket. archsusedebian
CVE-2018-0735 low 2.5 The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in O… archsusedebian
CVE-2018-6942 low 2.5 An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file. archdebian
CVE-2018-9234 low 2.5 GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with acce… archsusedebian
CVE-2018-12699 low 2.5 2y ago Low: binutils security update debiansuserockylinux
CVE-2018-20673 low 2.5 5y ago Low: gcc security and bug fix update debiansuserockylinux
CVE-2018-7263 low 2.5 6y ago Low: GStreamer, libmad, and SDL security, bug fix, and enhancement update rockylinux
CVE-2018-19841 low 2.5 6y ago Low: wavpack security update suserockylinuxdebian
CVE-2018-19840 low 2.5 6y ago Low: wavpack security update suserockylinuxdebian
CVE-2018-10393 low 2.5 7y ago Low: libvorbis security update susedebianrockylinux
CVE-2018-10392 low 2.5 7y ago Low: libvorbis security update susedebianrockylinux
CVE-2018-18751 low 2.5 7y ago Low: gettext security update archsusedebianrockylinux